RuPay BEPG
When you request an authorization using a supported card type and a supported processor, you can include payer authentication data in the request.
There are two versions of RuPay available for Bharat Ecommerce Payment Gateway (BEPG):
Redirection flow: the customer is redirected from the merchant to an authentication page hosted by the issuer.
Seamless flow: the customer goes to an authentication page hosted on your website (merchant). You can use either a token or an account number in an authorization request.
For seamless flow, your system must be Payment Card Industry Data Security Standard (
PCIDSS) compliant. You might have to use a token to ensure PCI DSS compliance.
Before implementing payer authentication, contact customer support to have your account configured for this feature.
Supported Processor
- RuPay
Endpoints
POST /pts/v2/payments
POST /pts/v2/payments
POST /pts/v2/payments
Fields Specific to the Bharat Ecommerce Payment Gateway Use Case
orderInformation.amountDetails.currency
Set the value to INR.
Authorizations Using Redirection Flow
Redirection flow authenticates the customer by directing the customer from the merchant site to an authentication page that is hosted by the issuer.
Example
{ "clientReferenceInformation": { "code": "12345678" }, "consumerAuthenticationInformation": { "cavv": "MTAM123M456M789", "xid": "1234567890" }, "processingInformation": { "commerceIndicator": "rpy" }, "orderInformation": { "billTo": { "country": "US", "lastName": "Doe", "address2": "Unit 123456", "address1": "12345 Main Street", "postalCode": "48104-2201", "locality": "Ann Arbor", "administrativeArea": "MI", "firstName": "John", "phoneNumber": "999999999", "district": "MI", "buildingNumber": "123", "company": "Visa", "email": "[email protected]" }, "amountDetails": { "totalAmount": "12456.00", "currency": "INR" } }, "paymentInformation": { "card": { "expirationYear": "2031", "number": "41111111XXXXXXX1", "securityCode": "123", "expirationMonth": "12", "type": "061" } }}{ "_links": { "authReversal": { "method": "POST", "href": "/pts/v2/payments/6443452051237111442758/reversals" }, "self": { "method": "GET", "href": "/pts/v2/payments/6443452051237111442758" }, "capture": { "method": "POST", "href": "/pts/v2/payments/6443452051237111442758/captures" } }, "clientReferenceInformation": { "code": "TC50171_3" }, "id": "6443452051237111442758", "orderInformation": { "amountDetails": { "authorizedAmount": "12456.00", "currency": "INR" } }, "paymentAccountInformation": { "card": { "brandName": "RUPAY", "type": "061" } }, "paymentInformation": { "tokenizedCard": { "type": "061" }, "card": { "type": "061" } }, "processorInformation": { "approvalCode": "183217", "networkTransactionId": "100000000000000000000000025253", "transactionId": "100000000000000000000000025253", "responseCode": "00", "avs": { "code": "2" } }, "status": "AUTHORIZED", "submitTimeUtc": "2022-02-08T18:33:30Z"}Required Fields
These fields are required when you use an account number in an authorization request for seamless flow. The values for these fields are in the response from the payer authentication validate service. When you request the payer authentication validate and authorization services together, the data is automatically passed from one service to the other.
| Field | Description |
|---|---|
aggregatorInformation.aggregatorId | Required for an aggregator or seller. Otherwise, this field is optional. |
aggregatorInformation.submerchant.merchantId | Required for an aggregator or seller only when aggregatorInformation.aggregatorId is not present in the response from the payer authentication validate service. Otherwise, this field is optional. |
aggregatorInformation.submerchant.name | Required for an aggregator or seller. Otherwise, this field is optional. |
clientReferenceInformation.code | Order reference or tracking number. Provide a unique value for each transaction so that you can perform meaningful searches for the transaction. |
deviceInformation.httpAcceptBrowserValue | — |
deviceInformation.ipAddress | — |
deviceInformation.userAgentBrowserValue | — |
orderInformation.amountDetails.totalAmount | — |
orderInformation.amountDetails.currency | Set the value to INR. |
orderInformation.billTo.address1 | — |
orderInformation.billTo.administrativeArea | — |
orderInformation.billTo.country | — |
orderInformation.billTo.email | — |
orderInformation.billTo.firstName | — |
orderInformation.billTo.lastName | — |
orderInformation.billTo.locality | — |
orderInformation.billTo.postalCode | — |
payerAuthentication.authenticationValue | — |
paymentInformation.card.expirationMonth | — |
paymentInformation.card.expirationYear | — |
paymentInformation.card.securityCode | — |
paymentInformation.card.number | — |
processingInformation.commerceIndicator | Set the value to rpy. |
Optional Fields
You can use these optional fields to include additional information when processing an authorization using the redirection flow method.
Optional Fields
| Field | Description |
|---|---|
merchantInformation.categoryCode | — |
merchantInformation.merchantDescriptor.contact | — |
merchantInformation.merchantDescriptor.locality | — |
merchantInformation.merchantDescriptor.name | — |
merchantInformation.merchantDescriptor.postalCode | — |
merchantInformation.transactionLocalDateTime | If you do not send this field, the system time in Indian Standard Time (IST) is used. |
Authorizations Using Seamless Flow with an Account Number (No Token)
Seamless flow authenticates the customer during an online purchase and protects payment information with a one-time password that is hosted on your website. This section explains how to authorize Seamless Flow transactions using an account number in the authorization request.
Example
{ "clientReferenceInformation": { "code": "RTS-Auth" }, "processingInformation": { "commerceIndicator": "rpy", "capture":"true" }, "orderInformation": { "billTo": { "country": "IN", "lastName": "Doe", "firstName": "John", "address2": "test", "address1": "12345 Main St.", "locality": "48104 2201", "administrativeArea": "TN", "phoneNumber": "999999999", "postalCode": "411040", "district": "MI", "buildingNumber": "123", "company": "Visa", "email": "[email protected]" }, "amountDetails": { "totalAmount": "100.00", "currency": "inr" } }, "paymentInformation": { "card": { "expirationYear": "2031", "number": "41111111XXXXXXX1", "securityCode": "123", "securityCodeIndicator": "1", "expirationMonth": "12", "type": "061" } }, "deviceInformation": { "httpAcceptBrowserValue": "123456", "ipAddress": "10.10.10.10", "userAgentBrowserValue": "aa" }, "aggregatorInformation": { "subMerchant": { "name": "rupay" } }, "merchantInformation": { "merchantDescriptor": { "administrativeArea": "AN", "postalCode": "123324", "transactionLocalDateTime":"19255610122021", "contact":"23423423423" } }, "consumerAuthenticationInformation": { "transactionToken": "MTAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDI1MjM2" }}{ "_links": { "authReversal": { "method": "POST", "href": "/pts/v2/payments/6385272861347128228688/reversals" }, "self": { "method": "GET", "href": "/pts/v2/payments/6385272861347128228688" }, "capture": { "method": "POST", "href": "/pts/v2/payments/6385272861347128228688/captures" } }, "clientReferenceInformation": { "code": "RTS-Auth" }, "id": "63852728665346435458228688", "orderInformation": { "amountDetails": { "authorizedAmount": "100.00", "currency": "inr" } }, "paymentAccountInformation": { "card": { "brandName": "RUPAY", "type": "061" } }, "paymentInformation": { "tokenizedCard": { "type": "061" }, "card": { "type": "061" } }, "processorInformation": { "approvalCode": "123456", "networkTransactionId": "100000000000000000000000025253", "transactionId": "100000000000000000000000025253", "responseCode": "00", "avs": { "code": "2" } }, "status": "AUTHORIZED", "submitTimeUtc": "2021-12-03T10:28:06Z"}Required Fields
These fields are required when you use an account number in an authorization request for seamless flow. The values for these fields are in the response from the payer authentication validate service. When you request the payer authentication validate and authorization services together, the data is automatically passed from one service to the other.
| Field | Description |
|---|---|
aggregatorInformation.aggregatorId | Required for an aggregator or seller. Otherwise, this field is optional. |
aggregatorInformation.submerchant.merchantId | Required for an aggregator or seller only when aggregatorInformation.aggregatorId is not present in the response from the payer authentication validate service. Otherwise, this field is optional. |
aggregatorInformation.submerchant.name | Required for an aggregator or seller. Otherwise, this field is optional. |
clientReferenceInformation.code | Order reference or tracking number. Provide a unique value for each transaction so that you can perform meaningful searches for the transaction. |
deviceInformation.httpAcceptBrowserValue | — |
deviceInformation.ipAddress | — |
deviceInformation.userAgentBrowserValue | — |
orderInformation.amountDetails.totalAmount | — |
orderInformation.amountDetails.currency | Set the value to INR. |
orderInformation.billTo.address1 | — |
orderInformation.billTo.administrativeArea | — |
orderInformation.billTo.country | — |
orderInformation.billTo.email | — |
orderInformation.billTo.firstName | — |
orderInformation.billTo.lastName | — |
orderInformation.billTo.locality | — |
orderInformation.billTo.postalCode | — |
payerAuthentication.authenticationValue | — |
paymentInformation.card.expirationMonth | — |
paymentInformation.card.expirationYear | — |
paymentInformation.card.securityCode | — |
paymentInformation.card.number | — |
processingInformation.commerceIndicator | Set the value to rpy. |
Optional Fields
You can use these optional fields to include additional information when processing an authorization using the seamless flow with an account number (no token) method.
Optional Fields
| Field | Description |
|---|---|
merchantInformation.categoryCode | — |
merchantInformation.merchantDescriptor.contact | — |
merchantInformation.merchantDescriptor.locality | — |
merchantInformation.merchantDescriptor.name | — |
merchantInformation.merchantDescriptor.postalCode | — |
merchantInformation.transactionLocalDateTime | If you do not send this field, the system time in Indian Standard Time (IST) is used. |
Authorizations Using Seamless Flow with a Token
Seamless flow authenticates the customer during an online purchase and protects payment information using a one-time password that is hosted on your website. This section explains how to authorize seamless flow transactions using a token in the authorization request.
Example
{ "clientReferenceInformation": { "code": "RTS-Auth" }, "processingInformation": { "commerceIndicator": "rpy" }, "orderInformation": { "billTo": { "country": "US", "lastName": "Doe", "address2": "Apt. 2", "address1": "123456 Main St.", "postalCode": "560066", "locality": "94043", "administrativeArea": "CA", "firstName": "John", "phoneNumber": "999999999", "district": "MI", "buildingNumber": "123", "company": "Visa", "email": "[email protected]" }, "amountDetails": { "totalAmount": "100.00", "currency": "inr" } }, "paymentInformation": { "tokenizedCard": { "number": "41111111XXXXXXX1", "transactionType": "1", "expirationYear": "2031", "securityCode": "123", "securityCodeIndicator": "1", "expirationMonth": "12", "cryptogram": "abcdefgh" } }, "consumerAuthenticationInformation": { "transactionToken": "MTAwMDAwM1234567890", "authenticationTransactionContextId": "123456789012345678901234567890" }, "deviceInformation": { "ipAddress": "10.10.10.10", "httpAcceptBrowserValue": "text/html", "userAgentBrowserValue" : "Mozilla/5.0 (compatible; MSIE 9.0; Windows Phone OS 7.5; Trident/5.0; IEMobile/9.0)" }, "aggregatorInformation": { "subMerchant": { "name": "rupay" } }, "merchantInformation": { "merchantDescriptor": { "administrativeArea": "AN", "postalCode": "123324", "transactionLocalDateTime":"19255610122021", "contact":"23423423423" } }}{ "_links": { "authReversal": { "method": "POST", "href": "/pts/v2/payments/6383780039607106528664/reversals" }, "self": { "method": "GET", "href": "/pts/v2/payments/6383780039607106528664" }, "capture": { "method": "POST", "href": "/pts/v2/payments/6383780039607106528664/captures" } }, "clientReferenceInformation": { "code": "RTS-Auth" }, "id": "6383780039607106528664", "orderInformation": { "amountDetails": { "authorizedAmount": "100.00", "currency": "inr" } }, "paymentAccountInformation": { "card": { "brandName": "RUPAY", "type": "061" } }, "paymentInformation": { "tokenizedCard": { "type": "061" }, "card": { "type": "061" } }, "processorInformation": { "approvalCode": "235426", "networkTransactionId": "100000000000000000000000025253", "transactionId": "100000000000000000000000025253", "responseCode": "00", "avs": { "code": "2" } }, "status": "AUTHORIZED", "submitTimeUtc": "2021-12-01T17:00:04Z"}Required Fields
These fields are required when you use a token in an authorization request for Seamless Flow. The values for these fields are in the response from the payer authentication validate service. When you request the payer authentication validate and authorization services together, the data is automatically passed from one service to the other.
| Field | Description |
|---|---|
aggregatorInformation.aggregatorId | Required for an aggregator or seller. Otherwise, this field is optional. |
aggregatorInformation.subMerchant.id | Required for an aggregator or seller when aggregatorInformation.aggregatorId is not present in the response from the payer authentication validate service. Otherwise, this field is optional. |
aggregatorInformation.submerchant.name | Required for an aggregator or seller. Otherwise, this field is optional. |
clientReferenceInformation.code | Order reference or tracking number. Provide a unique value for each transaction so that you can perform meaningful searches for the transaction. |
consumerAuthenticationInformation.authenticationTransactionContextId | — |
consumerAuthenticationInformation.transactionToken | Set the value to the token sent by RuPay. The response from the payer authentication validate service contains the token. |
deviceInformation.httpAcceptBrowserValue | — |
deviceInformation.ipAddress | — |
deviceInformation.userAgentBrowserValue | — |
merchantInformation.transactionLocalDateTime | — |
orderInformation.amountDetails.totalAmount | — |
orderInformation.amountDetails.currency | Set the value to INR. |
orderInformation.billTo.address1 | — |
orderInformation.billTo.administrativeArea | — |
orderInformation.billTo.country | — |
orderInformation.billTo.email | — |
orderInformation.billTo.firstName | — |
orderInformation.billTo.lastName | — |
orderInformation.billTo.locality | — |
orderInformation.billTo.postalCode | — |
paymentInformation.tokenizedCard.cryptogram | — |
paymentInformation.tokenizedCard.expirationMonth | — |
paymentInformation.tokenizedCard.expirationYear | — |
paymentInformation.tokenizedCard.number | — |
paymentInformation.tokenizedCard.securityCode | — |
paymentInformation.tokenizedCard.transactionType | Set the value to 1. |
processingInformation.commerceIndicator | Set the value to rpy. |
Thanks for your feedback!
Last published: September 29, 2026